Junglewise Threat Intelligence

CVE-2026-49792: Microsoft Windows ReFS numeric truncation code execution

CVE-2026-49792 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows 10 Version 21H2, Microsoft Windows 10 Version 1607, Microsoft Windows 11 Version 26H1, Microsoft Windows 11 Version 24H2, Microsoft Windows 10 Version 1809, Microsoft Windows 10 Version 22H2, Microsoft Windows 10, Microsoft Windows Server 2016, Microsoft Windows 11, Microsoft Windows 11 Version 25H2. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Windows Resilient File System (ReFS), a component used to manage and protect data on storage drives. An attacker who already has basic access to a computer could exploit this flaw to run unauthorized code with higher privileges. This could lead to a full system takeover, allowing the attacker to view sensitive data, modify files, or disrupt operations.

Technical details

A numeric truncation error (CWE-197) exists in the Windows Resilient File System (ReFS) driver. The vulnerability is triggered when the system incorrectly handles integer conversions, potentially leading to memory corruption. An attacker with local access and low-level privileges can exploit this to execute arbitrary code in the context of the kernel or a highly privileged service. The attack vector is local and requires no user interaction. Microsoft has released security updates to address this issue across affected Windows 10, Windows 11, and Windows Server versions.

Affected products

  • Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9339
  • Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
  • Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
  • Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
  • Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
  • Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
  • Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2269
  • Microsoft Windows Server 2016 10.0.14393.0 to 10.0.14393.9339

Timeline

  • 2026-07-14: disclosed: Initial publication of CVE-2026-49792 by Microsoft and NVD.
  • 2026-07-14: patched: Security updates made available via Microsoft Update Guide.

References

Related threats